Not sure where to start? Answer 3 questions and get a tailored compliance action plan.
What applies to me? →UN Independent International Scientific Panel on AI: Preliminary Report on Agentic AI Governance
Issued by
UN Independent International Scientific Panel on AI
The UN Independent International Scientific Panel on AI released a preliminary report establishing governance expectations for agentic AI systems, covering human oversight, incident reporting, and audit trail requirements. It applies to organizations deploying autonomous or semi-autonomous AI agents capable of taking consequential actions without direct human instruction at each step. The report calls for documented intervention thresholds, standardized incident registers, and verifiable provenance records for agentic decision outputs.
Applies To
Overview
This preliminary report from the UN IISPA addresses the governance gap that arises when AI systems operate with extended autonomy, executing multi-step tasks across tools, data sources, and external services. Its scope encompasses enterprise and public-sector deployments of agentic AI, including AI orchestration platforms, autonomous workflow agents, and AI systems integrated into operational decision chains. Key provisions specify criteria for meaningful human oversight, require organizations to define and document the conditions under which human intervention must occur, and mandate retention of decision traces sufficient to reconstruct agentic actions after the fact. The report also introduces a standardized template for incident reporting, including near-miss events and unintended actions, to support international data sharing on agentic AI failures. As a preliminary report, it does not yet carry binding legal force, but member states and standards bodies are expected to reference its provisions in subsequent regulatory instruments. Organizations should treat its requirements as indicative of the compliance baseline that is likely to crystallize in forthcoming binding frameworks.
Key Requirements
- •Establish and document explicit human-oversight criteria, including defined intervention thresholds for agentic AI systems
- •Maintain decision traces and provenance records for all consequential agentic actions, with retention periods subject to further guidance
- •Implement a structured incident register capturing unintended actions, near misses, and out-of-bounds behaviors by agentic systems
- •Report qualifying incidents using the Panel's standardized reporting template, enabling cross-border aggregation of agentic AI failure data
- •Conduct periodic audits of agentic system behavior against documented oversight criteria and intervention thresholds
- •Preserve chain-of-provenance documentation for data and instructions passed to agentic systems throughout task execution
What Your Organization Must Do
- →Inventory all agentic AI systems in production or under evaluation, and classify each by the degree of operational autonomy and potential consequence of unsupervised actions
- →Define and formally document intervention thresholds for each agentic deployment, specifying the conditions that require a human operator to pause, redirect, or terminate agent activity
- →Implement logging architecture that captures full decision traces at each agentic step, ensuring logs are tamper-evident and retained in a retrievable format
- →Establish an incident register and intake process covering unintended agentic actions and near misses, assigning ownership to a named compliance or risk function
- →Update AI procurement and vendor contracts to require provenance documentation and audit-trail capabilities from any third-party agentic AI platform
- →Engage legal and risk teams now to assess how the Panel's framework aligns with existing obligations under the EU AI Act and OECD AI Principles, reducing duplication of compliance effort
Playbook Guidance
Step-by-step implementation guidance for compliance teams.
Frequently Asked Questions
- Is the UN IISPA agentic AI report legally binding on companies operating in EU or OECD member states?
- The preliminary report carries no binding legal force in its current form. However, OECD member states and standards bodies are expected to incorporate its provisions into forthcoming regulatory instruments, making early alignment a practical risk-reduction strategy for organizations already subject to the EU AI Act.
- What qualifies as an 'agentic AI system' under the UN IISPA framework and does it cover third-party orchestration platforms?
- The framework applies to autonomous or semi-autonomous AI systems capable of taking consequential multi-step actions without direct human instruction at each step. This explicitly includes AI orchestration platforms and workflow agents sourced from third-party vendors, so procurement contracts should require provenance and audit-trail capabilities from those suppliers.
- What specific incident reporting obligations does the UN IISPA agentic AI report introduce?
- Organizations must maintain a structured incident register capturing unintended actions, near misses, and out-of-bounds agent behaviors. Qualifying incidents must be reported using the Panel's standardized template, which is designed to support cross-border aggregation of agentic AI failure data across member states.
- How do the UN IISPA human oversight requirements for agentic AI differ from EU AI Act human oversight obligations?
- The EU AI Act requires human oversight as a high-risk system characteristic, while the UN IISPA framework goes further by mandating formally documented intervention thresholds that specify the exact conditions triggering operator action. Legal teams should map both frameworks simultaneously to avoid duplicating compliance infrastructure.
- What decision trace and audit trail retention requirements apply under the UN IISPA agentic AI report?
- Organizations must retain tamper-evident decision traces sufficient to reconstruct agentic actions after the fact, along with chain-of-provenance records for all data and instructions passed to agents throughout task execution. Specific retention periods remain subject to further guidance from the Panel.
- When should compliance teams begin implementing UN IISPA agentic AI governance controls given the report's draft status?
- Given the August 2026 effective date and the report's expected influence on binding instruments under the EU AI Act and OECD AI Principles, compliance teams should begin inventorying agentic deployments and drafting intervention threshold documentation now. Retroactive compliance against multi-system logging requirements is operationally costly to remediate under time pressure.
